Hello,

I've run into the issue detailed at
https://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security

Understandably I don't have the skills to modify checkpassword so if I do
the suggested will it work?

If you can't change the script, you can make Dovecot's checkpassword-reply
binary setuid or setgid (e.g. chgrp dovecot
/usr/libexec/dovecot/checkpassword-reply; chmod g+s
/usr/libexec/dovecot/checkpassword-reply)



-- 
Best regards,
 Niamh                          mailto:ni...@fullbore.co.uk

Reply via email to